Cybersecurity leaders want new hires contributing within 90 days. Most wait twice that long. And by the time a new analyst is finally up to speed, the skills of the people around them may already be slipping.
That's the cycle at the center of the 2026 SkillBit Micro-Training Survey Report, "The Shift to Continuous Cybersecurity Micro-Training." Commissioned by Bellini Capital and CyberBay, with micro-training provider SkillBit guiding the areas of inquiry, the study surveyed 202 North American decision makers: CIOs, CISOs, and IT, InfoSec, and security operations leaders. More than 88% work at organizations with more than 1,000 employees, and more than 80% spent their entire 2025 training budget.
So, money isn't the problem. The report makes a case that the model is.
The talent problem begins at the front door. Seventy percent of organizations have no junior roles, or very few, that they can fill with candidates who have less than two years of experience. The report calls this what it is: a self-imposed talent shortage. Organizations say they need new people, then write job requirements that screen them out.
There are signs of movement. Thirty percent of leaders are already receptive to interactive lab formats as a substitute for traditional credentials, and another 49.5% would be open to them with convincing evidence that they work. Testing a candidate in a live environment, rather than reading a resume, could widen the pipeline without lowering the bar.
The stakes go beyond filling this year's requisitions.
"The long-term risk is a pipeline that runs dry," said Diana Kelley, CISO at Noma Security. "Cut off the early-career pathways and you lose the next generation of defenders." She advocates for deliberate on-ramps such as apprenticeships, AI-amplified junior roles, and academic pipelines tied to real work. "The organizations that thrive will be the ones that figure out how to onboard new employees quickly, and use AI to make junior practitioners more capable, rather than replace them," Kelley said.
AI uncertainty is tightening that funnel further. "Many organizations are slowing hiring while they wait to see how AI agents will actually perform," said Robb Reck, Chief Information, Trust, and Security Officer at Pax8. "The candidates who are getting hired? Those who lead with an AI-first mindset and can articulate how they'll drive transformation, not just use the tools."
Time-to-value: the hidden risk window
Once someone is hired, the clock starts. And it runs long.
-
64% of executives consider three months an acceptable time-to-value for a new cybersecurity hire.
-
57% report that it actually takes six months.
-
64% see a gap of at least three months between what they expect and what they get.
The report describes that gap as a "hidden risk" period: months in which a seat is filled on the org chart but not yet in the SOC.
What slows people down is telling. The top drivers are foundational, not tool-specific. General IT knowledge (55%) and cybersecurity processes (50%) were rated the most significant causes of delay. Tool knowledge ranked lower. The report's read is that organizations may be hiring for familiarity with a product stack while missing the broader IT and security fundamentals that today's hiring inputs don't measure well.
Then the skills start slipping
Getting people ready is only half the problem. Keeping them ready is the other half.
Thirty-nine percent of executives cite skills decay as a problem on their teams, and the report attributes the acceleration largely to the pace of AI-driven change. It says the issue is sharper at scale, with 60% of organizations with 50,000 or more employees citing decay.
Among leaders who reported decay, 75% described it as a moderate irritation, and the biggest casualty was team readiness. That was rated a 4 or 5 in significance by 44% of those respondents, ahead of morale, training costs, and staffing flexibility.
"Cybersecurity training must be ongoing, not occasional," said Shane Barney, CISO at Keeper Security. "AI streamlines detection and efficiency, but it still relies on human oversight and sound governance to operate securely."
Certifications work. The calendar doesn't
None of this is an indictment of certifications. Eighty-four percent of organizations sponsor certification training, with vendor-specific certs, CISSP, CompTIA Security+, and CCSP leading the list. More than 96% report at least some positive impact on staff effectiveness, and 41% report a strong impact.
But how that training is delivered is another story. Seventy-one percent of executives would prefer 20-minute weekly micro-training sessions over 30 to 40 hours of training once or twice a year.
The reason is familiar to anyone who has run a security team: 47.5% cite urgent tasks, the daily fires, as the primary reason development goals get missed. A week-long course competes with incident response and loses. A 20-minute session can fit around it.
Ram Varadarajan, CEO at Acalvio, says the fix is to stop treating learning as optional. "To overcome training-time and onboarding challenges, organizations should treat learning as a business requirement with protected time and measurable goals." He notes that this is a real shift from a few years ago, when training was seen as discretionary spending.
Asked whether it's better to be an expert on the organization's tech stack or proficient in problem solving across any stack, roughly two-thirds of respondents chose problem solving.
The report uses a car technician analogy. A certified tool expert can read one brand's diagnostic computer; a "star" understands how the engine works and can diagnose any vehicle. When executives rated what defines their own top performers, the leading traits were strong curiosity about technical problems, proactive learning habits, strong forensics capability, and deep knowledge of the environment. Years of experience and relevant certifications ranked near the bottom of the list.
[RELATED: How to Start a Career in Cybersecurity the Right Way]
That lines up with how AI is changing the analyst's job. "A strong analyst used to be measured by how well they could investigate an alert, write a detection, or analyze an incident themselves," said Aviv Nahum, Co-Founder and CEO at Above Security. "Increasingly, they'll be measured by how effectively they can define the objective, give the right context to a set of agents, evaluate the result, and decide what should happen next."
Nahum is clear that this raises the bar rather than lowering it: "That makes technical depth more important, not less. You need enough understanding to know when an agent is wrong, what context it is missing, and whether the result makes sense in the environment."
Sumedh Thakar, President and CEO at Qualys, sees the same dividing line: "The human-in-loop approach to AI is here to stay, and that will separate those with the expertise to guide, shape, and govern AI from those who will be replaced by it," he said.
The boardroom blind spot
Here's where the data get uncomfortable.
When asked how well they can provide objective data that validate team readiness, 96% of executives expressed confidence: 59% somewhat and 37% extremely. Confidence in spotting high-potential talent was nearly identical.
But when asked what they actually rely on when reporting readiness to the board, the answers told a different story. Verbatim responses cited personal observation, trust, and anecdotal notes. One executive put it bluntly: "Board tends to not want a full update unless something has happened."
The report concludes that most readiness reporting is a patchwork of audit results, performance reviews, and certification counts, none of which necessarily shows whether a team can stop a live breach. There is no industry readiness standard. Leaders feel confident, but the evidence behind that confidence is largely subjective.
What this means for security leaders
The report's prescription is continuous readiness: ongoing assessment, hands-on practice, and bite-sized learning built into the operational flow rather than scheduled around it. It's worth remembering that the study was guided by a micro-training vendor, and its sample leans toward IT leadership rather than CISOs. Still, the underlying tensions will be familiar to most security leaders, and several practical moves follow from them.
Audit your junior requirements. If most entry-level roles demand two or more years of experience, the talent shortage is partly self-inflicted. Hands-on lab assessments offer a way to validate ability without the resume filter.
Onboard for fundamentals, not just tools. The biggest drags on time-to-value are IT knowledge and security processes. Build onboarding around those, and treat the three-month gap between expectation and reality as measurable risk.
Protect the time, and make it small. Training that loses to urgent work every week isn't a training program. Short, recurring sessions have a better chance of surviving the SOC's reality.
Hire and develop for judgment. As agents take on more execution, the premium shifts to curiosity, forensics, environmental context, and the technical depth needed to know when the machine is wrong.
Bring evidence to the board. "Trust me" isn't a readiness metric. Until the industry defines a standard, leaders who can show objective, performance-based data on their teams will have an advantage in every budget conversation.
The report puts it simply: the future of cybersecurity workforce development won't be measured by the number of certifications on a wall, but by proof that the team is ready for the threats in front of it.

